Splunk Search

How to search with variables from lookup csv?

fishmong3r
Explorer

Let's say I have a search and a very basic lookup table (csv). What I want to achieve is to use the values in the table for my search.

So my table.csv:

id name
1 first
2 second
3 third

 

Now, I want to simply run a query like which returns every single log that has any of the id's from my lookup table.

index=myIndex sourcetype=mySourcetype id IN somelookup ---- where id is in table.csv's id column.

 

The second challenge then would be to actually have the name column values added as a field to the results for clarity.

Labels (2)
0 Karma
1 Solution

ITWhisperer
SplunkTrust
SplunkTrust

Try something like this

index=myIndex sourcetype=mySourcetype [ | inputlookup table.csv | fields id ]
| lookup table.csv

View solution in original post

ITWhisperer
SplunkTrust
SplunkTrust

Try something like this

index=myIndex sourcetype=mySourcetype [ | inputlookup table.csv | fields id ]
| lookup table.csv

fishmong3r
Explorer

For that, I get "Error in 'lookup' command: Must specify one or more lookup fields."

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust
| lookup table.csv id
0 Karma

fishmong3r
Explorer

lovely!

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Design, Compete, Win: Submit Your Best Splunk Dashboards for a .conf26 Pass

Hello Splunkers,  We’re excited to kick off a Splunk Dashboard contest! We know that dashboards are a primary ...

May 2026 Splunk Expert Sessions: Security & Observability

Level Up Your Operations: May 2026 Splunk Expert Sessions Whether you are refining your security posture or ...

Network to App: Observability Unlocked [May & June Series]

In today’s digital landscape, your environment is no longer confined to the data center. It spans complex ...